8.8
CVSSv3

CVE-2022-1227

Published: 29/04/2022 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A privilege escalation flaw was found in Podman. This flaw allows an malicious user to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

podman project podman

psgo project psgo

redhat enterprise linux workstation 7.0

redhat enterprise linux 7.0

redhat enterprise linux server 7.0

redhat enterprise linux for power little endian 7.0

redhat enterprise linux for ibm z systems 7.0

redhat enterprise linux 8.0

redhat developer tools 1.0

redhat quay 3.0.0

redhat openshift container platform 4.0

redhat enterprise linux server for power little endian update services for sap solutions 8.6

redhat enterprise linux for ibm z systems 8.6

redhat enterprise linux server aus 8.6

redhat enterprise linux server tus 8.6

redhat enterprise linux eus 8.6

redhat enterprise linux for power little endian 8.6

redhat enterprise linux server update services for sap solutions 8.6

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #1020907 golang-github-containers-psgo: CVE-2022-1227 Package: src:golang-github-containers-psgo; Maintainer for src:golang-github-containers-psgo is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Vignesh Raman <vigneshraman@collaboracom> Date: Wed, 28 Sep 2022 10:33 ...
Synopsis Important: container-tools:rhel8 security and bug fix update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 84 Extend ...
Synopsis Important: container-tools:rhel8 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Li ...
Synopsis Important: container-tools:30 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the container-tools:30 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security ...
Synopsis Important: podman security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for podman is now available for Red Hat Enterprise Linux 7 ExtrasRed Hat Product Security has rated this update as havi ...
Synopsis Important: container-tools:30 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the container-tools:30 module is now available for Red Hat Enterprise Linux 84 Extended Update Suppor ...
Synopsis Important: container-tools:20 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the container-tools:20 module is now available for Red Hat Enterprise Linux 82 Extended Update Suppor ...
Synopsis Important: OpenShift Container Platform 4658 packages and security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4658 is now available with updates to pac ...

Github Repositories

A script for exploiting CVE-2022-1227

CVE-2022-1227_Exploit A script for exploiting CVE-2022-1227 Background Ubuntu 2010 is recommanded Podman <400; 344 is recommanded TODO: add what is the principle of this vulnerability Install podman Follow the instruction in the official document: podmanio/getting-started/installation#installing-on-linux For Ubuntu 2010, the imstall command should b